漏洞列表 352547
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13987
Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Deletion
MEDIUM 4.3 2025-12-12
codnloc Purchase and Expense Manager
CVE NVD
CVE-2025-13314
Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.5 - Missing Authorization to Unauthenticated Plugin Settings Modification
MEDIUM 5.3 2025-12-12
markutos987 Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus
CVE NVD
CVE-2025-13885
Zenost Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
MEDIUM 6.4 2025-12-12
imran3229 Zenost Shortcodes
CVE NVD
CVE-2025-14062
Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter
MEDIUM 4.3 2025-12-12
tekafran Animated Pixel Marquee Creator
CVE NVD
CVE-2025-12963
LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation
CRITICAL 9.8 2025-12-12
lazycoders LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart
CVE NVD
CVE-2025-14132
Category Dropdown List <= 1.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
MEDIUM 6.1 2025-12-12
pandikamal03 Category Dropdown List
CVE NVD
CVE-2025-13971
TWW Protein Calculator <= 1.0.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Header' Setting
MEDIUM 4.4 2025-12-12
thewellnessway TWW Protein Calculator
CVE NVD
CVE-2025-13906
WP Flot <= 0.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
MEDIUM 6.4 2025-12-12
ysh WP Flot
CVE NVD
CVE-2025-13988
评论小秘书 <= 1.3.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
MEDIUM 6.1 2025-12-12
thobian 评论小秘书
CVE NVD
CVE-2025-13966
Paypal Payment Shortcode <= 1.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttom_image' Shortcode Attribute
MEDIUM 6.4 2025-12-12
sonlamtn200 Paypal Payment Shortcode
CVE NVD
CVE-2025-13961
Data Visualizer <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
MEDIUM 6.4 2025-12-12
subhransu-sekhar Data Visualizer
CVE NVD
CVE-2025-13884
Hide Email Address <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
MEDIUM 6.4 2025-12-12
buntegiraffe Hide Email Address
CVE NVD
CVE-2025-14035
DebateMaster <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Color Options via 'debate' Shortcode
MEDIUM 4.4 2025-12-12
jeremybmerrill DebateMaster
CVE NVD
CVE-2025-13840
BUKAZU Search widget <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'shortcode' Shortcode Attribute
MEDIUM 6.4 2025-12-12
bobvanoorschot BUKAZU Search widget
CVE NVD
CVE-2025-13960
GPXpress <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
MEDIUM 6.4 2025-12-12
davidkeen GPXpress
CVE NVD
CVE-2025-13320
WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter
MEDIUM 6.8 2025-12-12
wpusermanager WP User Manager – User Profile Builder & Membership
CVE NVD
CVE-2025-13440
Premmerce Wishlist for WooCommerce <= 1.1.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion
MEDIUM 5.3 2025-12-12
premmerce Premmerce Wishlist for WooCommerce
CVE NVD
CVE-2025-14392
Simple Theme Changer <= 1.0. - Missing Authorization to Plugin Settings Update via AJAX Actions
MEDIUM 4.3 2025-12-12
darendev Simple Theme Changer
CVE NVD
CVE-2025-14032
Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Parameter in 'bold_timeline_group' Shortcode
MEDIUM 6.4 2025-12-12
boldthemes Bold Timeline Lite
CVE NVD
CVE-2025-13969
Reviews Sorted <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'space' Shortcode Attribute
MEDIUM 6.4 2025-12-12
eurisko Reviews Sorted
CVE NVD